GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Soatok Dreamseeker (soatok@furry.engineer)

  1. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Friday, 13-Feb-2026 09:11:45 JST Soatok Dreamseeker Soatok Dreamseeker

    People can't help but try to evangelize Matrix in response to things I wrote, so I just disclosed a few more issues to Matrix's cryptography.

    This time, the issues were in their Rust library, vodozemac.

    One of them was pretty fucking stupid.

    In conversation about 13 hours ago from furry.engineer permalink
  2. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Friday, 13-Feb-2026 06:14:22 JST Soatok Dreamseeker Soatok Dreamseeker
    in reply to
    • Q ✨
    • Sophie Schmieg

    @sophieschmieg @q same

    In conversation about 16 hours ago from gnusocial.jp permalink
  3. Embed this notice
    Xe :verified: (cadey@pony.social)'s status on Friday, 13-Feb-2026 01:45:38 JST Xe :verified: Xe :verified:

    The Discourse has been Automated

    https://xeiaso.net/notes/2026/the-discourse-has-been-automated/?utm_campaign=mi_irl&utm_medium=social&utm_source=mastodon

    In conversation about 20 hours ago from pony.social permalink Repeated by soatok
  4. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Friday, 13-Feb-2026 01:45:02 JST Soatok Dreamseeker Soatok Dreamseeker
    • Riley S. Faelan

    @riley @ariadne My project https://publickey.directory makes this a dumb HTTP call.

    In conversation about 20 hours ago from furry.engineer permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: publickey.directory
      Public Key Directory - Key Transparency for the Fediverse
  5. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Friday, 13-Feb-2026 00:57:03 JST Soatok Dreamseeker Soatok Dreamseeker
    in reply to
    • Foxarc

    @Foxarc lmao that would be hilarious

    In conversation about 21 hours ago from furry.engineer permalink
  6. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Friday, 13-Feb-2026 00:45:11 JST Soatok Dreamseeker Soatok Dreamseeker

    RE: https://furry.engineer/@soatok/116055556402436098

    By the way, I'm not giving them 90 days this time.

    Last time I did that, they didn't bother to actually fix anything, so they didn't actually need any of that time. So they lost that privilege.

    Expect a public disclosure / write-up as soon as I feel like it.

    In conversation about 21 hours ago from furry.engineer permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Soatok Dreamseeker (@soatok@furry.engineer)
      from Soatok Dreamseeker
      People can't help but try to evangelize Matrix in response to things I wrote, so I just disclosed a few more issues in Matrix's cryptography to their `security@` email address. This time, the issues were in their Rust library, vodozemac. One of them was pretty fucking stupid. I'll do a better write-up than I was initially planning when they've had time to fix it.
  7. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Friday, 13-Feb-2026 00:28:58 JST Soatok Dreamseeker Soatok Dreamseeker

    @chuff Happens, no worries

    In conversation about 22 hours ago from furry.engineer permalink
  8. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Thursday, 12-Feb-2026 22:16:06 JST Soatok Dreamseeker Soatok Dreamseeker

    @shitpostalotl I ask myself that same question.

    This is why I stop myself from looking at rando projects when people toss "But what about Slopchat?" my way in response to one og my blogs on something unrelated.

    In conversation about a day ago from furry.engineer permalink
  9. Embed this notice
    [object Object] (zzt@mas.to)'s status on Thursday, 12-Feb-2026 22:12:03 JST [object Object] [object Object]

    “can you recommend an alternative?” no. that’s why I’m so fucking angry. we fucked it. we’re no longer capable of making online chat protocols or web browsers or discussion forum software that people actually want to use. it’s all shit. every choice is either proprietary and exploitative or awful open source garbage sucking all the air out of all alternatives and forks, operated by fucking terrible people. we let this happen.

    you want there to be an alternative so you can skip being angry too.

    In conversation about a day ago from mas.to permalink Repeated by soatok
  10. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Thursday, 12-Feb-2026 21:59:29 JST Soatok Dreamseeker Soatok Dreamseeker
    in reply to
    • Socketwench
    • nathanael

    @nathanael @socketwench Many reasons, acrually.

    If evrything is encrypted, then that fact ceases to be remarkable. More chaff, less wheat. More noise, less signal. It also becomes less special and people stop treating it like uber secret spy comms for ultra leet opsec. It's just chat.

    But it also keeps plaintext off the server. Service operators don't get legal demands to surrender evidence they don't have. It makes federation less risky for smaller nodes.

    It also makes E2EE table stakes. Which means services that follow suit have less data to get breached, or to train an AI on.

    Ubiquitous enceyption is just a damn good idea.

    In conversation about a day ago from furry.engineer permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.deda.group
      Dedagroup Business Solutions - Home
      from FlexCMP
      Consulenza e soluzioni capaci di supportare l’evoluzione digitale dei modelli di business dei nostri clienti, coniugando asset e piattaforme software con una profonda conoscenza dei processi del settore
  11. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Thursday, 12-Feb-2026 12:55:15 JST Soatok Dreamseeker Soatok Dreamseeker

    People can't help but try to evangelize Matrix in response to things I wrote, so I just disclosed a few more issues in Matrix's cryptography to their security@ email address.

    This time, the issues were in their Rust library, vodozemac.

    One of them was pretty fucking stupid.

    I'll do a better write-up than I was initially planning when they've had time to fix it.

    In conversation about a day ago from furry.engineer permalink
  12. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Thursday, 12-Feb-2026 12:51:12 JST Soatok Dreamseeker Soatok Dreamseeker
    in reply to
    • :copyleft: Kiri :tux:

    @kiri Given that my previous disclosure was in May 2024 (published August 2024), and then https://furry.engineer/@soatok/116055556402436098...

    Yeah, probably not.

    In conversation about a day ago from furry.engineer permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: furry.engineer
      Soatok Dreamseeker (@soatok@furry.engineer)
      10.9K Posts, 2.22K Following, 7.99K Followers · He/him. Gay/demi dhole (Cuon Alpinus) furry. Blogger, programmer, security engineer, cryptography nerd. 30+ Too spicy for Twitter (banned with all the prominent journalists on 2022-12-16) I don't represent any company, individual, or community.
  13. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Thursday, 12-Feb-2026 12:28:50 JST Soatok Dreamseeker Soatok Dreamseeker
    in reply to
    • Luna Lactea

    @jackemled https://web.archive.org/web/20260211235740/https://news.ycombinator.com/item?id=46979742#46982871

    In conversation about a day ago from furry.engineer permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: web.archive.org
      Discord Alternatives | Hacker News
  14. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Thursday, 12-Feb-2026 11:28:58 JST Soatok Dreamseeker Soatok Dreamseeker

    @chuff https://furry.engineer/@soatok/116054674014648064

    In conversation about a day ago from furry.engineer permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: furry.engineer
      Soatok Dreamseeker (@soatok@furry.engineer)
      from Soatok Dreamseeker
      Attached: 1 image @kavuskazian@gulp.cafe That's a good point. I added this to the article:
  15. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Thursday, 12-Feb-2026 10:09:27 JST Soatok Dreamseeker Soatok Dreamseeker
    in reply to
    • 「Carmilla」 luné's villain era

    @lunemercove Haha fair

    In conversation about a day ago from gnusocial.jp permalink
  16. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Thursday, 12-Feb-2026 10:09:10 JST Soatok Dreamseeker Soatok Dreamseeker
    in reply to

    The crucial thing Arathorn hasn't figured out is he's his own worst enemy when it comes to public relations.

    Several folks have told me they stopped trusting Matrix. But not because of my write-up. They stopped trusting Matrix because of how Matrix responded to my write-up.

    They couldn't just said something banal like, "Thanks for contributing to the security of Matrix," and done less damage to their own reputation.

    In conversation about a day ago from furry.engineer permalink
  17. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Thursday, 12-Feb-2026 10:02:38 JST Soatok Dreamseeker Soatok Dreamseeker
    in reply to

    There are more pathetic comments on the Hacker News thread.

    For example:

    (Would you believe this guy has -18 karma?)

    In conversation about a day ago from furry.engineer permalink

    Attachments


    1. https://furry.engineer/system/media_attachments/files/116/054/956/756/444/587/original/72f3cb092c8f5bfe.png
  18. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Thursday, 12-Feb-2026 09:45:53 JST Soatok Dreamseeker Soatok Dreamseeker
    in reply to
    • Tom Bortels

    @tbortels The situation today: Discord is centralized but has the budget for lawyers.

    A "decentralized" Discord without E2EE will result in people that want to host them to get hammered with legal demands for content and metadata that they do not have the resources to defend against, all under the illusion of decentralization.

    You might call such an outcome Robustness Theater, in the spirit of Bruce Schneier's term, Security Theater.

    In conversation about a day ago from furry.engineer permalink
  19. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Thursday, 12-Feb-2026 09:14:28 JST Soatok Dreamseeker Soatok Dreamseeker
    in reply to

    The Matrix guy is incentivized to control the narrative here. No surprise there.

    But I implore anyone paying attention to critically evaluate the facts and what he said then as well as what he's saying now.

    In conversation about a day ago from furry.engineer permalink
  20. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Thursday, 12-Feb-2026 09:06:36 JST Soatok Dreamseeker Soatok Dreamseeker
    in reply to
    • Beau

    @mochabeau Yes. It, like XMPP, has a plaintext mode, which means it's not in the same league as Signal to begin with. (And some asshole talking over me to tell people to use Matrix instead of Signal is what prompted me to even look at their code then.)

    In conversation about a day ago from furry.engineer permalink
  • Before

User actions

    Soatok Dreamseeker

    Soatok Dreamseeker

    He/him. Gay/demi dhole (Cuon Alpinus) furry.Blogger, programmer, security engineer, cryptography nerd. 30+Too spicy for Twitter (banned with all the prominent journalists on 2022-12-16)I don't represent any company, individual, or community.

    Tags
    • (None)

    Following 0

      Followers 1

      • GNU Too

      Groups 0

        Statistics

        User ID
        34725
        Member since
        21 Nov 2022
        Notices
        819
        Daily average
        1

        Feeds

        • Atom
        • Help
        • About
        • FAQ
        • TOS
        • Privacy
        • Source
        • Version
        • Contact

        GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

        Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.